Falhas do tipo CWE-476

2.321 resultados

Desreferenciação de ponteiro nulo autenticado

O software permite que um usuário autenticado force a desreferenciação de um ponteiro ou referência nula, tipicamente ao passar valores inesperados ou inválidos a uma função. O aplicativo não valida adequadamente a entrada antes de usá-la, causando falha (crash) ou comportamento indefinido que pode levar a negação de serviço.

Exemplo

Um painel administrativo aceita um ID de usuário para deletar, mas não verifica se esse ID existe no banco antes de acessar seus atributos. Um admin autenticado passa ID=0 ou um valor que não corresponde a nenhum registro, e o código tenta acessar propriedades de um objeto nulo, derrubando a aplicação.

Como mitigar

Sempre valide e verifique que referências/ponteiros são válidos antes de desreferenciar: teste se o objeto existe, se o ID é válido e se está dentro do escopo esperado. Use assertions em desenvolvimento e tratamento de exceções robusto em produção para falhas inesperadas.

CVE-2025-0430HIGHBelledonne Communications Linphone-Desktop NULL Pointer DereferenceEPSS 0.5%CVE-2023-37456The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS <EPSS 0.5%CVE-2024-3184MEDIUMMultiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when compiled with the ME_GOAEPSS 0.5%CVE-2025-53598LOWQsync CentralEPSS 0.5%CVE-2025-54148LOWQsync CentralEPSS 0.5%CVE-2026-23948MEDIUMFreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()EPSS 0.5%CVE-2021-33798MEDIUMA null pointer dereference was found in libpano13, version libpano13-2.9.20. The flow allows attackers to cause a denial of service and poteEPSS 0.5%CVE-2025-54146LOWQsync CentralEPSS 0.5%CVE-2018-5449A NULL Pointer Dereference issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. The application does EPSS 0.5%CVE-2026-55204HIGHHAProxy - NULL Pointer Dereference in hpack_dht_insert FunctionEPSS 0.5%CVE-2022-2874MEDIUMNULL Pointer Dereference in vim/vimEPSS 0.5%CVE-2024-2551HIGHPAN-OS: Firewall Denial of Service (DoS) Using a Specially Crafted PacketEPSS 0.5%CVE-2024-57435MEDIUMIn macrozheng mall-tiny 1.0.1, an attacker can send null data through the resource creation interface resulting in a null pointer dereferencEPSS 0.5%CVE-2024-45239HIGHAn issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync oEPSS 0.5%CVE-2026-77692HIGHUnauthenticated remote crash of named via a single DoH SIG(0) requestEPSS 0.5%CVE-2021-20196A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/write ioport commandsEPSS 0.5%CVE-2022-36000MEDIUMNull dereference on MLIR on empty function attributes in TensorFlowEPSS 0.5%CVE-2022-36011MEDIUMNull dereference on MLIR on empty function attributes in TensorFlowEPSS 0.5%CVE-2025-47808MEDIUMIn GStreamer through 1.26.1, the subparse plugin's tmplayer_parse_line function may dereference a NULL pointer while parsing a subtitle fileEPSS 0.5%CVE-2024-25177HIGHLuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of SeEPSS 0.5%